Last updated: July 26, 2026
Switching Auditors · Compliance Q&A

Does a new auditor accept my old SOC 2 evidence?

Often yes, but they must re-test it themselves. A new auditor can review evidence and prior reports you provide, yet independence rules mean they form their own conclusions rather than relying on the previous firm's work.

The full answer

A new firm will happily accept your underlying evidence, such as access logs, policies, tickets, and configurations, as inputs. What it cannot do is inherit the prior auditor's opinion. Under the AICPA's SSAE No. 18 standards, each auditor must gather sufficient evidence and reach independent conclusions, so they re-test the controls rather than trusting another firm's testing.

For a Type 2, the evidence must cover the observation window your new report will address (usually three to twelve months, with three months the shortest window most auditors accept). Evidence from a prior period supports history and context but does not substitute for samples pulled from the new window.

Your prior SOC 2 reports still help. Shared under NDA since they are confidential, they let the new firm understand your scope, system description, and prior control set, which speeds planning and scoping. Some findings and management responses from the old report also flag areas to tighten before fieldwork.

If your evidence already lives in a GRC platform like Vanta, Drata, Secureframe, or Sprinto, the transition is smoother: auditors with confirmed platform integrations pull evidence directly, so switching firms rarely means rebuilding your evidence trail from scratch.

Go deeper

Short answer not enough? These pages cover the full picture:

How switching auditors works ›  ·  SOC 2 audit cost data ›

Thinking about switching auditors?

See how the switch works, what carries over, and get comparable quotes from firms that fit your stack.

Start the switch →

Talk to auditors who handle this every week

Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.

All auditor profiles ›

Related questions

Can I switch SOC 2 auditors mid-cycle?

Yes. No AICPA rule locks you to one auditor. It is cleanest to switch between report periods, but you can change mid-cycle if your current engagement has not started fieldwork or has stalled.

Can I use a different auditor for Type 1 and Type 2?

Yes. Type 1 and Type 2 are separate engagements, so you can use different CPA firms for each. Many companies do, though keeping one firm can streamline the Type 2 since it already knows your controls.

Do I lose my SOC 2 history if I change auditors?

No. You keep every SOC 2 report you have already received, and your control and evidence history stays yours. A new auditor builds on that record; changing firms does not erase your prior reports.

How do I switch SOC 2 auditors?

Wait until your current report is issued, gather your scope and prior reports, request quotes from new firms, sign an engagement letter, and hand over your system description and evidence. No AICPA approval or transfer process is required.

How much can I save by switching SOC 2 auditors?

Potentially thousands, depending on scope. US SOC 2 audits range from $5,000 to $60,000-plus, while audits booked through the AuditNex network start at $2,500 and average about $5,000, so overpaying firms leave real room to save.

When is the best time to switch SOC 2 auditors?

Right after your current report is issued and before your next observation period begins. That timing avoids splitting a Type 2 window, keeps coverage continuous, and gives the new firm a clean period to plan.

All compliance questions ›

Sources: AICPA SSAE No. 18 attestation standards; AICPA auditor independence rules; AICPA and market practice on SOC 2 Type 2 windows, 2026. Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.